Security & trust

Your clients trust you. You can trust this.

What we do with the data your firm and your clients put in — stated plainly, including what is still to be confirmed.

Encrypted credential & DSC vault

Portal logins and DSC details are encrypted with AES-256-GCM before they are stored. Revealing one requires a reason, and the reveal is logged against the person.

Audit log

Document downloads by staff, credential reveals, sign-offs and other key events are written to an audit log you can filter and export as CSV.

Client files are never parsed

Uploads are stored as opaque bytes and handed back exactly as sent. Nothing reads inside a client's Tally backup, bank statement or bill photos.

Access you control

Roles for partner, manager, staff and article. Revoke a client contact and their session ends on their next request. Downloads are limited to firm staff or the holder of that request's link.

No passwords for clients

Clients use a one-time code on their registered mobile, or a single-purpose magic link. There is no client password to leak.

Payments verified server-side

A browser saying “paid” is never enough: every Razorpay payment signature is recomputed on the server, and anything that doesn't match is refused.

DPDP Act

Rights your clients can use

Under the Digital Personal Data Protection Act, 2023, your clients can see what is held about them and ask for it to be exported or erased. In CA Bundals, those requests come from the client's own portal into a queue your firm handles.

  • Consent recorded with its date
  • Export request — the client's data, downloadable
  • Deletion request — handled by the firm, subject to what the law requires you to retain
  • Notification preferences set by the client

Still to be confirmed

Where data is hosted: India — to be confirmed at launch.

Backups and retention: Daily backups kept 14 days and weekly backups kept 8 weeks, once app hosting goes live.

Encryption in transit: HTTPS on every page.

Certifications: none claimed. No external audit yet.

Report a vulnerability: info@bundals.com

Questions from your IT or audit team?

We'll answer them in writing.